A Guide to Threat Hunting in a SOC
ID: 2a4492a0-c7ff-559e-ae46-339106afc1d2
STIX ID: report--2a4492a0-c7ff-559e-ae46-339106afc1d2
Feed Name: On the Hunt
Threat Score
**Executive summary:** This post advocates a proactive, research-driven threat hunting approach and demonstrates practical hunts for lateral movement using Cobalt Strike and Impacket (e.g., WMIExec and Cobalt Strike Jump), providing example Sysmon events, command-line patterns, registry/service artifacts, admin-share file paths, sample queries, and a recommended hunt lifecycle to convert high-confidence hunts into detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
